How else do you suggest to store persistent login data?
This avoids most cross site scripting attacks
A refresh often just gets a new one, as they're usually valid for 5 mins or even less.
Better to have the auth server issue a single-use token that gets exchanged for a properly scoped session cookie on the app (sub)domain.
Edit: Of course, then you also need some sort on central session storage, to properly deal with logging out.